MyInvoice-SDK-Middleware

Security Policy

Supported Versions

We release security patches for the latest minor version only.

Reporting a Vulnerability

Do not open a public issue for security vulnerabilities.

Instead:

  1. Open a GitHub Security Advisory (preferred)
  2. Or email the maintainers privately

Include:

Response Timeline

Credential Safety

Digital Signing Security

The middleware supports X.509 certificate-based document signing. Follow these practices:

Private Key Protection

Certificate Handling

Sensitive Data Logging

The middleware redacts the following from all logs:

Test Fixtures

All test certificates and keys in packages/signing/test/fixtures/ are:

Scope

This policy covers the MyInvois Middleware codebase. For MyInvois API issues, contact LHDN directly.